About the Role
Semgrep is building the systems that encode security research into automated detection and remediation at scale. You'll set your own research direction, ship to security teams worldwide, and have access to a vast corpus of real-world code, a program analysis engine, frontier models, and a platform reaching millions of developers. You'll blend application security, program analysis, and applied AI to solve the core problem: making automated detection you can actually trust—grounded in reproducible program analysis (taint, reachability, precise code context) rather than guesswork.
About the Company
Semgrep is the leader in code security for builders. Founded in San Francisco and backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital, Semgrep is recognized by Gartner in Application Security Testing and trusted by organizations including Vanta, Lyft, and Dropbox. Learn more at semgrep.dev.
Responsibilities
- Design and ship security workflows combining deterministic analysis (taint, reachability, static slicing) with LLM reasoning to find real vulnerabilities (SSRF, IDOR, injection, auth gaps, supply-chain risk) across languages and frameworks.
- Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy—atomic, well-scoped steps grounded in deterministic context, with attention to hallucination, confidence calibration, and sensitive code handling.
- Close the gap between "a finding exists" and "this finding is real and worth a developer's time" through work on automated triage, validation, and scaling beyond manual review.
- Design benchmarks and evaluation loops grounded in real customer codebases to assess when workflows deliver quality.
- Model vulnerability classes, taint sources/sinks/sanitizers, and security properties as reusable, versioned logic that scales across ecosystems.
- Learn unfamiliar languages, frameworks, and technologies quickly—understand how vulnerabilities manifest and turn that into detection.
- Partner with Engineering and Product to prototype and validate new capabilities, writing real code with strong customer focus.
- Publish blog posts, give talks, and represent Semgrep's research to the wider security community.
- Set research direction based on industry trends, emerging threats, and the field's trajectory, turning that into work that advances products and the broader security community.
Requirements
- Strong application security expertise: deep knowledge of vulnerability classes, how they arise and manifest across languages and frameworks, with ability to dive into details.
- Proven experience finding vulnerabilities and explaining their impact and context to developers responsible for fixes (as security researcher, consultant, or security engineer).
- Genuine fluency writing and auditing code in two or more languages—enough to build tools and prototypes, not just read code.
- Builder's mindset: you prefer automating problems to manual work, and you get satisfaction from tooling that scales impact.
- Real curiosity about or hands-on experience with applied AI/LLMs (agentic workflows, prompt engineering, RAG, evals, LLM tool use) and clear judgment about where models help and where they don't.
- Experience building or operating LLM/agent systems in production: pydantic-ai, MCP, multi-provider orchestration, eval frameworks, cost/latency awareness.
- Strong desire to keep learning and genuine excitement (not reluctance) when handed unfamiliar languages, frameworks, or technologies.
- Comfort operating with autonomy: break ambiguous problems into milestones, drive forward, and own outcomes without close oversight.
- Enjoyment in sharing knowledge through writing, talks, and teaching both inside and outside Semgrep.
Nice to Have
- Program analysis or compiler background: ASTs, IRs, call graphs, data-flow/taint analysis, points-to/alias analysis, or static analysis internals.
- Experience with SAST tooling or Semgrep (as user, competitor, or contributor).
- Familiarity with distributed/durable workflow systems, graph databases, or cloud-native infrastructure (Kubernetes, Argo, Temporal).
- Track record at fast-paced startups or similarly minded teams in larger companies.
- Published or presented security research.
- Experience training or fine-tuning small/local language models for security or code tasks, especially where sensitive code cannot be sent to third-party providers.
Benefits
- Competitive salary: $190,000 – $319,000 (varies by location), with equity and additional benefits.
- Market-aligned benefits program that meets or exceeds local standards across hiring regions (details at Semgrep Benefits).
- Transparent compensation bands updated to stay above market averages for comparable roles.
- Access to a transparent culture where you can see and influence company decisions.
Location: Remote – US (currently hiring in Arizona, California, Colorado, Connecticut, District of Columbia, Florida, Georgia, Illinois, Maryland, Massachusetts, Michigan, Missouri, Nebraska, New Jersey, New York, North Carolina, Oregon, Tennessee, Texas, Virginia, Washington, and Wisconsin).
Note: Prior experience in a fast-paced tech environment helps, but we prioritize your curiosity, security instincts, and appetite for building. If this role excites you but you don't meet every requirement, apply anyway. Semgrep is an equal-opportunity employer seeking diverse backgrounds and experiences.